Skip to content

HumanSignal security advisories

12 advisories across Label Studio

Company profile
DateAdvisory
Jan 12Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
CVE-2026-22033Highno fix yet
May 152025label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
CVE-2025-47783Highfixed in 1.18.0
Feb 142025Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
CVE-2025-25297High8.6fixed in 1.16.0
Feb 142025Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
CVE-2025-25296Medium6.1fixed in 1.16.0
Feb 222024Label Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config
CVE-2024-26152Medium4.7fixed in 1.11.0
Jan 312024Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
CVE-2023-47116Medium5.3fixed in 1.11.0
Jan 242024Cross-site Scripting Vulnerability on Data Import
CVE-2024-23633Medium4.7fixed in 1.10.1
Jan 242024Cross-site Scripting Vulnerability on Avatar Upload
CVE-2023-47115High7.1fixed in 1.9.2
Nov 142023Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
CVE-2023-47117High7.5fixed in 1.9.2.post0
Nov 92023Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session Tokens
CVE-2023-43791Critical9.8fixed in 1.8.2
Mar 242023Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/
GHSA-cpmr-mw4j-99r7High7.5fixed in 1.7.2
Oct 42022Heartex - Label Studio Community Edition vulnerable to SSRF in the Data Import module
CVE-2022-36551High6.5fixed in 1.6.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.